Security Analysis of Wireless Home Monitoring Units in the Pacemaker Ecosystem

Anniken Wium Lie · NORA - Norwegian Open Research Archives · 2019

An increasing number of medical devices are being connected to the Internet, thereby broadening their attack surface. Some people’s lives depend on these devices, hence it is of vital importance that they are secure. A pacemaker is an example of such device, communicating with other devices of what is referred to as the pacemaker ecosystem. However, the communication protocols in use are proprietary and kept secret by manufacturers. This makes it challenging to verify whether sufficient security has been implemented. Previous research has disclosed several vulnerabilities in similar systems. In this thesis, we investigate devices from Biotronik, a leading German manufacturer. We perform a security analysis of the communication protocols between different Home Monitoring Unit (HMU) models and a Data Server. An HMU is a device that transmits patient data from a pacemaker to a Data Server where health-care personnel can access the information. The communication is based on GSM, a wireless communication standard with several well-known security vulnerabilities. These vulnerabilities allow us to eavesdrop on the communication by setting up an illegitimate Base Transceiver Station (BTS) which the HMUs connect to. Using Commercial off-the-shelf (COTS) equipment and decommissioned HMUs from eBay, we demonstrate how reverse engineering of the communication protocol is possible for some of the HMU models. Our analysis results in the identification of several protocol and implementation weaknesses, and demonstrates how attack vectors can be exploited. We also validate that our findings apply to older HMU models still in use by patients. While we have discovered several vulnerabilities, our study also suggest that Biotronik have made efforts to implement security mechanisms in all their HMU models, and that their newer models are significantly more resistant to security attacks.

Read the paper · More papers on PaperTik